Home > Blog > ISC2 Certified Information Systems Security Professional > Common Criteria (ISO 15408) for CISSP: A Deep Dive

Common Criteria (ISO 15408) for CISSP: A Deep Dive

Deep Dive Cert Sensei Team 2033-01-29 10 min read

Common Criteria (ISO 15408) is an international standard for computer security certification. For the CISSP exam, you must distinguish between Protection Profiles (user requirements), Security Targets (vendor claims), and Evaluation Assurance Levels (EAL 1-7), which measure the depth and rigor of the security evaluation performed by an independent body.

#CISSP #Common Criteria #ISO 15408 #Security Architecture #ISC2

What exactly is Common Criteria (ISO 15408)?

If you've spent any time in Domain 3 (Security Architecture and Engineering), you know that 'trust' is a tricky thing in IT. You can't just take a vendor's word that their firewall is 'military grade.' That's where Common Criteria (CC), formally known as ISO 15408, comes into play. It provides a standardized framework for vendors to make security claims and for independent labs to verify those claims.

Think of it as a universal language for security. Instead of every company inventing their own way to describe security features, CC gives us a consistent set of terminology. For the CISSP exam, you don't need to memorize the entire ISO document, but you do need to understand the mechanism of how a product gets certified. It's all about removing the guesswork from procurement by ensuring that the security functions of a Target of Evaluation (TOE) are documented and tested against a rigorous set of criteria.

What is the difference between a Protection Profile (PP) and a Security Target (ST)?

This is a classic CISSP exam trap. To get these right, think of it as a job interview. The Protection Profile (PP) is the job description. It's created by a user or a government agency to define the security requirements for a specific category of product—like a smart card or a network firewall. It says, 'Whatever product fills this role must be able to do X, Y, and Z.'

The Security Target (ST), on the other hand, is the candidate's resume. It is written by the vendor. The ST describes exactly how the specific product (the TOE) meets the requirements laid out in the PP. While a PP is generic to a class of products, the ST is specific to one single product. If you see a question asking which document defines the 'user's needs,' the answer is always the Protection Profile. If it asks which document defines the 'vendor's implementation,' go with the Security Target.

How do Evaluation Assurance Levels (EAL) actually work?

You'll see EALs ranging from 1 to 7, and it's tempting to think that EAL 7 is 'more secure' than EAL 1. Stop right there—that's a dangerous assumption. EALs do not measure the strength of the security features; they measure the *assurance* that the features were implemented correctly. In other words, EAL measures the depth and rigor of the evaluation process, not the quality of the product itself.

EAL 1 is basically 'functionally tested,' meaning the vendor says it works and a lab did a quick check. EAL 4 is the common benchmark for commercial products, involving a methodical test and review of the design. EAL 7 is the gold standard, requiring formal verification of the design and testing—usually reserved for extremely high-risk environments like military kernels. When studying, remember: a product with EAL 2 and a great security design is safer than a product with EAL 5 and a terrible design.

Who is the Certification Body and what do they do?

The certification process isn't a DIY project. It involves a strict separation of duties to prevent conflicts of interest. First, you have the Evaluation Facility (the lab). These are the technical experts who dig into the code, run the tests, and verify that the Security Target (ST) matches the actual product. They produce an Evaluation Technical Report (ETR) detailing their findings.

Then comes the Certification Body. The Certification Body doesn't necessarily do the testing; instead, they review the ETR provided by the lab to ensure the evaluation was conducted according to the rules. Once they are satisfied, they issue the formal certificate. For your exam, remember this flow: Vendor $ ightarrow$ Evaluation Lab $ ightarrow$ Certification Body. This chain of trust ensures that the vendor isn't just grading their own homework.

How do you use Common Criteria for product procurement?

In a real-world CISO role, you'll use Common Criteria to mitigate supply chain risk. Instead of relying on a sales pitch, you ask the vendor for their CC Certification. You then check if the product was certified against a Protection Profile (PP) that matches your organization's needs. This ensures that the product meets a baseline of security that has been independently verified.

When procurement happens at a government level, CC is often a mandatory requirement. By specifying a required EAL level, an organization can decide how much risk they are willing to accept. If you're buying a basic office printer, EAL 2 might suffice. If you're buying a cross-domain solution for classified data, you'll demand EAL 6 or 7. This systematic approach removes subjectivity from the buying process and forces vendors to be transparent about their security architecture.

How can you master this for the CISSP exam?

Common Criteria can feel dry, but it's a high-yield topic in Domain 3. The key to mastering it is practicing the nuance between the terms. You need to be able to spot the difference between a PP and an ST in a complex scenario-based question. Don't just read the theory—apply it by solving problems that force you to choose the correct document or EAL level based on a given business requirement.

To help you nail this, we've built a powerhouse of resources at Cert Sensei. We offer 1,000 expert-curated ISC2 CISSP practice questions that mirror the actual exam's difficulty. Every single answer comes with detailed expert reasoning, so you aren't just guessing why you were wrong. Plus, our domain-level analytics allow you to see exactly where you're struggling in the Security Architecture and Engineering domain, so you can stop wasting time on what you already know and focus on the gaps.

❓ Frequently Asked Questions

Does a higher EAL always mean a product is more secure?

No. EAL measures the rigor of the evaluation process, not the effectiveness of the security controls. A product with a low EAL but a strong security architecture is more secure than a product with a high EAL and a weak architecture.


Can a product be certified against multiple Protection Profiles?

Yes. A single product (TOE) can be evaluated against multiple PPs if it fulfills the requirements of different product categories, such as being both a network switch and a firewall.


Is Common Criteria the same as FIPS 140-2?

No. While both are certifications, FIPS 140-2 specifically focuses on the security of cryptographic modules, whereas Common Criteria is a broader framework for any IT security product.

More from ISC2 Certified Information Systems Security Professional

🧠

Test Your Knowledge

Ready to practice Certified Information Systems Security Professional? Put what you've learned to the test.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium
📖 Browse the Glossary

Join thousands of certification students

Sign Up Free